Privacy Policy for the PERMA-Lead® App

Beta version, as of 1 October 2026

This privacy policy applies to the PERMA-Lead® App during its test phase (beta) on iOS and Android. It describes which data the app processes, where that data is stored and which rights you have. A separate privacy policy applies to our website. The German version of this policy is the authoritative one.

The app is under development. Individual features described here may still be missing or look different in the test version. We update this policy with every test version.

1. Controller

Next4Lead GmbH
Düsseldorfer Straße 9
63801 Kleinostheim
Germany

Represented by its managing director Jochen Gierl
Email for privacy requests: info@perma-lead-app.de

We have not appointed a data protection officer because the legal requirements for doing so are not met.

2. The essentials in brief

The app is built so that as little data as possible reaches our company.

  • Without an account, all your data stays on your device. Nothing is transferred to us.
  • With an account, content is stored in a database in Frankfurt am Main for backup and synchronization. See section 6.
  • Sign-in runs through Firebase Authentication by Google. This service is operated in the USA. See section 5.
  • The app contains no analytics or tracking tools. We only send crash reports if you have agreed beforehand. See section 11.
  • Your employer receives no usage data about you, even if it has licensed the app for you.
  • We treat your reflection texts as particularly sensitive. They are neither analyzed nor passed on to third parties.

3. Use without an account

You can use the app without registering. In that case the app stores all data exclusively in a local database on your device. This includes your settings, your initial self-assessment, completed and skipped impulses, impulses you have written yourself, reflections and reminder times.

This data does not leave your device. We have no access to it. If you delete the app, this data is gone.

On Android the database is excluded from the automatic cloud backup to Google Drive. When you switch to a new device it can be transferred through device migration.

Legal basis: No processing by us takes place. The app merely downloads editorial content (impulses) without transmitting any personal data.

4. Creating an account and signing in

An account is optional. You need one for backup and synchronization across several devices, for purchases and for use through a company license. You have three options.

  • Email address and password
  • Sign in with Google
  • Sign in with Apple

When you sign in with Google or Apple, we receive from the respective provider your email address (with Apple, an anonymized relay address if you choose), possibly your name, and a technical identifier. We never see the password for your Google or Apple account.

The data processed is your email address, display name (optional), sign-in method, a technical user identifier (UID), the time of registration and of the last sign-in, and the IP address during sign-in.

Purpose: Providing the account, assigning your data to you, protection against misuse.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

5. Sign-in service Firebase Authentication (Google, USA)

For registration and sign-in we use Firebase Authentication, a service of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, which is technically operated by Google LLC in the USA. Google processes the sign-in data named in section 4 in data centers in the USA. Your content (impulses, reflections, progress) is not affected by this. It is stored in Frankfurt (section 6).

The transfer to the USA is based on the European Commission's adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR). Google LLC is certified under this framework. In addition, the EU standard contractual clauses apply, which are part of our data processing agreement with Google.

We have built the app so that the sign-in service can be replaced by a European provider without your content having to be migrated.

You can find more information in the Firebase privacy information.

6. Backup and synchronization of your content

With an account, content is synchronized between your device and our database. The database is Cloud Firestore by Google, operated in the region europe-west3 (Frankfurt am Main). Our server functions (Cloud Functions) run in the same region.

Synchronization is intended for the following content.

  • Your profile (email, display name, PERMA focus, language, time zone, difficulty preference)
  • Your activities (which impulses you completed or skipped, with the date and the text of the impulse at the time of completion)
  • Your reflections (self-assessment in the five PERMA dimensions as numerical values, and your free texts for note and resolution)
  • Impulses you have written yourself
  • Your reminder settings
  • Your licenses, purchases and library access (read only, this data is written exclusively by our server)

Note for the beta phase: In the current test version, not all of the content listed is transferred yet. The app shows in your profile what is being backed up. Your answers from the initial self-assessment currently stay on your device, even if you create an account.

Only you can read and write your own data area. This is enforced by server-side access rules. Our staff only access content if you expressly ask us to as part of a support request.

Reflection texts. Your free texts in reflections may contain information about your mood, stress or personal environment. We do not analyze these texts, do not pass them on and do not use them for any purpose other than displaying them in your app. They are technically kept out of log files and error reports. When a reflection is deleted, the texts are overwritten immediately.

Purpose: Synchronization between your devices, restoring after a change of device, providing purchased or licensed content.

Legal basis: Art. 6(1)(b) GDPR (performance of a contract). To the extent that your reflection texts allow conclusions about your health, processing is based on your explicit consent under Art. 9(2)(a) GDPR, which you give when creating the account and can withdraw at any time with effect for the future. In the beta phase you give this consent by accepting the tester notice.

Processor: Google Ireland Limited (Google Cloud Platform, Firebase). A data processing agreement under Art. 28 GDPR is in place, based on the Google Cloud Data Processing Terms.

7. Reminders and push notifications

The app schedules reminders for impulses and reflections locally on your device. Nothing is transferred to us for this.

If you have a license or a subscription, the app additionally registers a device token with Firebase Cloud Messaging (Google). Through this token we send exactly one kind of message, namely the notice that your license has changed. The message contains no content, only an event type. The token is deleted as soon as no license exists any more.

Legal basis: Art. 6(1)(b) GDPR.

8. Purchases and subscriptions

Purchases and subscriptions are handled through the Apple App Store or Google Play. We do not see payment data. We receive a purchase receipt from the store, which our server verifies in order to unlock the purchased content. We store the type of purchase, the product identifier and the term.

The privacy policies of Apple or Google apply to the handling of the purchase. Purchases are not yet possible in the beta phase.

Legal basis: Art. 6(1)(b) GDPR.

9. Use through your employer

If your employer licenses the app for you, it invites you using your business email address. We store this invitation with your email address, the status and the time of activation. After activation, your account is linked to the license seat.

Your employer sees which seats are assigned and which content of its own it has provided. It sees no usage data. It learns neither which impulses you complete, nor how you reflect, nor whether you open the app at all. Technically, your activity data carries no company identifier, so this data does not come into existence in relation to your employer in the first place.

An exception is only possible if your employer has made an explicit agreement with its employees or the works council and confirms this to us. Only then can it activate an aggregated progress view. Every such activation is logged by us. This feature is not active in the beta phase.

For content provided by your employer, the employer is the controller within the meaning of the GDPR and we are its processor. For your account and your personal content, we remain the controller.

Legal basis: Art. 6(1)(b) GDPR (contract with you), Art. 28 GDPR (processing on behalf of your employer).

10. Security

The connection between app and server is encrypted. The local database is protected by the encryption of your operating system. Our server endpoints only accept requests from the genuine app (Firebase App Check with App Attest on iOS and Play Integrity on Android). Only our server can write license and access data.

We do not log content. Error messages in the app and on the server contain error codes, not user data.

11. No analytics, crash reports only with consent

The app contains no analytics or tracking tools. We do not collect usage statistics.

To find errors, we intend to use Firebase Crashlytics (Google). Crash reports are only sent if you have agreed to this in the app beforehand. A report contains technical details about the crash, the device model and the version of the operating system and of the app. It contains neither your user identifier nor your content. You can withdraw your consent in the app at any time.

Note for the beta phase: This feature is not yet built into the current test version. The app does not send crash reports to us. Section 13 applies to crashes that Apple records through TestFlight.

Legal basis: Art. 6(1)(a) GDPR and Section 25(1) TDDDG (consent).

12. Retention and deletion

We store your content for as long as your account exists.

You can delete individual content (reflections, your own impulses, activities) in the app. Technically, a deletion marker with an identifier and a timestamp remains so that the deletion is carried over to all your devices. All content fields are overwritten in the process.

You can delete your account in the app under “Data & Privacy”. This removes your account and your profile, your activities, notes and reflections, scheduled impulses and your own cards, your settings, your unlocks and purchases in the app, and all data on the device. A license seat through your organization becomes free. The connection to your Apple Account is removed.

A record that your account was deleted remains for a limited time so that a device that was offline in the meantime does not restore the data. Backup copies are overwritten after a fixed period. The app tells you this period before deletion. Data may remain on your other devices until you delete the app there.

Alternatively, we delete your account on request to info@perma-lead-app.de within seven days. After the end of the test phase we delete all test accounts.

We keep purchase receipts for as long as tax and commercial law obligations require.

13. Test version through TestFlight (iOS only)

In the beta phase we distribute the iOS app through TestFlight by Apple. In doing so, Apple collects your name and email address (anonymized when invited through a public link), device model, operating system version, number of sessions, crash reports, and feedback and screenshots that you send through TestFlight. Apple makes this information available to us in App Store Connect.

Apple Distribution International Ltd., Hollyhill Industrial Estate, Hollyhill, Cork, Ireland, is jointly responsible with us for this processing. The Apple privacy information on TestFlight applies.

Legal basis: Art. 6(1)(b) GDPR (participation in the test), Art. 6(1)(f) GDPR (error analysis).

14. Your rights

You have the following rights towards us regarding your personal data.

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection to processing based on legitimate interests (Art. 21 GDPR)
  • Withdrawal of consent with effect for the future (Art. 7(3) GDPR)

To exercise them, contact info@perma-lead-app.de. In the beta phase we prepare data access reports and exports manually and reply within one month.

15. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is the Bavarian State Office for Data Protection Supervision (BayLDA), Promenade 18, 91522 Ansbach, Germany, www.lda.bayern.de.

16. Changes

We adapt this privacy policy when the app or the legal situation changes. You can find the current version in the app and at perma-lead-app.de/en/privacy-policy-app. We will inform you in the app about material changes.